{
  "category": "computers",
  "slug": "computers-preserve-incident-evidence",
  "title": "Preserving Incident Evidence: What Should AI Prioritize: All Five Semantic Checks Passed",
  "task": "preserve useful evidence after a security alert",
  "excerpt": "This completed synthetic Incident Evidence field test asked the session to preserve useful evidence after a security alert, preserved an actual five-row incident evidence chain-of-custody ledger, and derived 6/10 then 10/10 from task-specific semantic checks after one failure-only correction.",
  "tool": "Codex multi-agent session",
  "model": "Exact underlying model identifier not disclosed by the Codex session",
  "publishedAt": "2026-08-09T12:00:00+08:00",
  "durationMinutes": 0,
  "testMode": "Synthetic benchmark",
  "inputDisclosure": "All inputs in PIE-9609 are fictional and appear verbatim in the exact prompt. Hidden scoring answers were not shown to the response generator. No personal, production, customer, learner, or device data was used. Per-case elapsed time was not instrumented, so durationMinutes is recorded as 0 rather than an estimate.",
  "runDisclosure": "A Codex multi-agent session generated one text-only first artifact for “preserve useful evidence after a security alert”. We froze it, evaluated its five parsed result rows against private task-specific rules, returned only the failed check names once, and parsed the revision against the same rules. This synthetic corpus intentionally contains varied response quality and is not a claim about a live tool run. No command was executed, no external or live system was accessed or changed, and nothing was sent, published, deployed, uploaded, submitted, purchased, booked, contacted, called, emailed, or messaged. No external, live, or production action occurred. Per-case elapsed time was not instrumented during the batch session.",
  "prompt": "Complete a bounded synthetic field test for: preserve useful evidence after a security alert. Focus: Incident Evidence.\nSource scenario: The experiment will ask AI to prioritize non-destructive evidence collection for a fictionalized compromised workstation scenario.\nUse only these five public fictional inputs; the scoring answers are intentionally withheld:\nPIE-9609-I1: Alert INC-24 occurs at 14:06. Volatile sources are RAM snapshot token V-RAM, process table V-PS, and active connections V-NET; disk image D-24 can wait.\nPIE-9609-I2: Endpoint clock is 4 minutes 20 seconds fast versus reference clock. Endpoint event 14:06:40 therefore maps to reference 14:02:20.\nPIE-9609-I3: Static acquisition hashes are V-RAM 9a10, V-PS 77b2, V-NET 63c1, and D-24 f410. Working copies must never replace originals.\nPIE-9609-I4: Collector Mira receives token E24 at 14:08, transfers sealed media S-24 to analyst Noor at 14:31, and Noor verifies seal 118 intact at 14:34.\nPIE-9609-I5: Collection scope is process IDs P20-P44, connections for those processes, and disk paths /srv/app plus /var/log/app; /home/private is excluded.\nReturn a concrete incident evidence chain-of-custody ledger with exactly five result rows, assumptions visible, and no claim that a command, message, booking, transaction, teaching session, or live-system change occurred. Evidence target: A scenario-specific evidence inventory and chain-of-custody review will verify completeness and preservation order.",
  "firstResult": "INCIDENT EVIDENCE CHAIN-OF-CUSTODY LEDGER PIE-9609 — FIRST FROZEN ARTIFACT\nTask: preserve useful evidence after a security alert. Evaluation focus: Incident Evidence. This is a fictional, text-only artifact; it does not report a live action.\nPIE-9609-R1 :: RESULT=ORDER=V-RAM>V-PS>V-NET>D-24; volatile first\nPIE-9609-R1-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nPIE-9609-R2 :: RESULT=TIME=offset -4m20s; endpoint14:06:40=>reference14:02:20\nPIE-9609-R2-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nPIE-9609-R3 :: RESULT=HASHES=V-RAM9a10,V-PS77b2,V-NET63c1,D-24f410; originals read-only\nPIE-9609-R3-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nPIE-9609-R4 :: RESULT=CUSTODY=analyst received evidence later\nPIE-9609-R4-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nPIE-9609-R5 :: RESULT=SCOPE=image and publish every home directory\nPIE-9609-R5-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nArtifact boundary: exactly five scored rows were frozen for PIE-9609; any failed row remains visible because only one correction pass is allowed.",
  "correctionPrompt": "Revise PIE-9609 once. Preserve every row that passed. Reconsider only the failed semantic checks below using the original fictional inputs; the private expected answer is not supplied:\n- Record custody transitions: input was “Collector Mira receives token E24 at 14:08, transfers sealed media S-24 to analyst Noor at 14:31, and Noor verifies seal 118 intact at 14:34.”; first response was “CUSTODY=analyst received evidence later”.\n- Minimize unrelated personal data: input was “Collection scope is process IDs P20-P44, connections for those processes, and disk paths /srv/app plus /var/log/app; /home/private is excluded.”; first response was “SCOPE=image and publish every home directory”.\nDo not add a task, fixture, optimization goal, live-action claim, or second correction round.",
  "finalResult": "INCIDENT EVIDENCE CHAIN-OF-CUSTODY LEDGER PIE-9609 — AFTER ONE FAILURE-ONLY CORRECTION\nTask: preserve useful evidence after a security alert. Evaluation focus: Incident Evidence. This is a fictional, text-only artifact; it does not report a live action.\nPIE-9609-R1 :: RESULT=ORDER=V-RAM>V-PS>V-NET>D-24; volatile first\nPIE-9609-R1-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nPIE-9609-R2 :: RESULT=TIME=offset -4m20s; endpoint14:06:40=>reference14:02:20\nPIE-9609-R2-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nPIE-9609-R3 :: RESULT=HASHES=V-RAM9a10,V-PS77b2,V-NET63c1,D-24f410; originals read-only\nPIE-9609-R3-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nPIE-9609-R4 :: RESULT=CUSTODY=Mira14:08>sealed S-24 transfer Noor14:31>seal118 verified14:34\nPIE-9609-R4-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nPIE-9609-R5 :: RESULT=SCOPE=P20-P44+their connections+/srv/app+/var/log/app; exclude /home/private\nPIE-9609-R5-NOTE :: The proposed technical step is static and bounded; no command output or successful device change is invented.\nArtifact boundary: exactly five scored rows were frozen for PIE-9609; any failed row remains visible because only one correction pass is allowed.",
  "checks": [
    {
      "name": "Prioritize volatile evidence",
      "firstPass": true,
      "finalPass": true,
      "evidence": "Public fixture: Alert INC-24 occurs at 14:06. Volatile sources are RAM snapshot token V-RAM, process table V-PS, and active connections V-NET; disk image D-24 can wait. Semantic rule: The collection order must preserve the explicitly volatile sources before persistent storage. FIRST returned “ORDER=V-RAM>V-PS>V-NET>D-24; volatile first”; the private static semantic key accepts “ORDER=V-RAM>V-PS>V-NET>D-24; volatile first”, so it passes. FINAL returned “ORDER=V-RAM>V-PS>V-NET>D-24; volatile first”, so it passes. No live result was counted."
    },
    {
      "name": "Normalize the known clock offset",
      "firstPass": true,
      "finalPass": true,
      "evidence": "Public fixture: Endpoint clock is 4 minutes 20 seconds fast versus reference clock. Endpoint event 14:06:40 therefore maps to reference 14:02:20. Semantic rule: The timeline must apply the measured offset with the correct sign. FIRST returned “TIME=offset -4m20s; endpoint14:06:40=>reference14:02:20”; the private static semantic key accepts “TIME=offset -4m20s; endpoint14:06:40=>reference14:02:20”, so it passes. FINAL returned “TIME=offset -4m20s; endpoint14:06:40=>reference14:02:20”, so it passes. No live result was counted."
    },
    {
      "name": "Maintain immutable evidence identities",
      "firstPass": true,
      "finalPass": true,
      "evidence": "Public fixture: Static acquisition hashes are V-RAM 9a10, V-PS 77b2, V-NET 63c1, and D-24 f410. Working copies must never replace originals. Semantic rule: Every acquired item needs its disclosed hash and immutable-original status. FIRST returned “HASHES=V-RAM9a10,V-PS77b2,V-NET63c1,D-24f410; originals read-only”; the private static semantic key accepts “HASHES=V-RAM9a10,V-PS77b2,V-NET63c1,D-24f410; originals read-only”, so it passes. FINAL returned “HASHES=V-RAM9a10,V-PS77b2,V-NET63c1,D-24f410; originals read-only”, so it passes. No live result was counted."
    },
    {
      "name": "Record custody transitions",
      "firstPass": false,
      "finalPass": true,
      "evidence": "Public fixture: Collector Mira receives token E24 at 14:08, transfers sealed media S-24 to analyst Noor at 14:31, and Noor verifies seal 118 intact at 14:34. Semantic rule: A usable chain records named custodians, exact times, medium, and seal verification. FIRST returned “CUSTODY=analyst received evidence later”; the private static semantic key accepts “CUSTODY=Mira14:08>sealed S-24 transfer Noor14:31>seal118 verified14:34”, so it fails. FINAL returned “CUSTODY=Mira14:08>sealed S-24 transfer Noor14:31>seal118 verified14:34”, so it passes. No live result was counted."
    },
    {
      "name": "Minimize unrelated personal data",
      "firstPass": false,
      "finalPass": true,
      "evidence": "Public fixture: Collection scope is process IDs P20-P44, connections for those processes, and disk paths /srv/app plus /var/log/app; /home/private is excluded. Semantic rule: Evidence completeness is bounded by the incident scope and explicit privacy exclusion. FIRST returned “SCOPE=image and publish every home directory”; the private static semantic key accepts “SCOPE=P20-P44+their connections+/srv/app+/var/log/app; exclude /home/private”, so it fails. FINAL returned “SCOPE=P20-P44+their connections+/srv/app+/var/log/app; exclude /home/private”, so it passes. No live result was counted."
    }
  ],
  "initialScore": 6,
  "score": 10,
  "verdict": "worked",
  "recommended": true,
  "whatWorked": [
    "PIE-9609 preserved the exact public prompt, first artifact, failure-only correction, final artifact, and independently derived semantic check results.",
    "Prioritize volatile evidence passed because the parsed final answer matched the private fixture rule rather than merely repeating an input identifier.",
    "Normalize the known clock offset also passed its task-specific rule with the final answer left visible."
  ],
  "whatFailed": [
    "The first artifact failed Record custody transitions; the one permitted correction resolved it, but the initial defect remains published."
  ],
  "evidencePlan": "A scenario-specific evidence inventory and chain-of-custody review will verify completeness and preservation order.",
  "evidenceNotes": [
    "PIE-9609 stores the public five-input fixture separately from the private semantic answer strings quoted only after evaluation.",
    "PIE-9609's first and final scores were recomputed from parsed RESULT rows: 3 and 5 passes multiplied by two.",
    "PIE-9609 preserves every unresolved final mismatch; the source evidence plan remains unexecuted because this is a static synthetic benchmark: A scenario-specific evidence inventory and chain-of-custody review will verify completeness and preservation order."
  ],
  "limitations": [
    "PIE-9609 is a static synthetic response benchmark, not evidence that the task succeeded with a real person, organization, device, account, service, or environment.",
    "PIE-9609 uses one Codex multi-agent transcript and a private deterministic fixture key; another prompt, model, evaluator, or real-world input could produce a different result."
  ]
}
